{ "version": "4.2", "name": "Detection Priority by Threat Actors", "description": "security_content detection priorty by common techniques used from threat actors", "domain": "mitre-enterprise", "techniques": [ { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1027", "score": 62, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___encoded_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_create_executable_file.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1193", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1598.002", "score": 58, "showSubtechniques": false }, { "techniqueID": "T1204.002", "score": 54, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/single_letter_process_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/drop_icedid_license_dat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/batch_file_write_to_system32.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/uncommon_processes_on_endpoint.yml" }, { "techniqueID": "T1566.001", "score": 37, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_suspicious_shared_file_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_mshta.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_executing_macro_code.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_bitsadmin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_spawned_child_process_to_download.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_rundll32_with_no_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winword_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawning_certutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_spawn_rundll32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshtml_module_load_in_office_product.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_document_creating_schedule_task.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_application_drop_executable.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_writing_cab_or_inf.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_spawning_control.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", "score": 53, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/download_files_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.001", "score": 39, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nishang_powershelltcponeline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_processing_stream_of_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadstring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/any_powershell_downloadfile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_domain_enumeration.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_4104_hunting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1086", "score": 55, "showSubtechniques": false }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1059.003", "score": 47, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_wake_on_lan_command.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/windows_connhost_exe_force_flag.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/first_time_seen_command_line_argument.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1060", "score": 45, "showSubtechniques": false }, { "techniqueID": "T1547.001", "score": 43, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/start_up_during_safe_mode_boot.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1071.001", "score": 41, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1598.003", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1192", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1566.002", "score": 36, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml" }, { "techniqueID": "T1070.004", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/clear_unallocated_sector_using_cipher_app.yml" }, { "techniqueID": "T1107", "score": 37, "showSubtechniques": false }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1082", "score": 35, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/system_information_discovery_detection.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1083", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1053.005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_within_public_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/winevent_scheduled_task_created_to_spawn_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml" }, { "techniqueID": "T1059.005", "score": 34, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/execute_javascript_with_jscript_com_clsid.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1078", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1003.001", "score": 21, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_into_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_comsvcs_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_credential_dumping_through_lsass_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dump_lsass_via_procdump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/access_lsass_memory_for_dump_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_using_loaded_images.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_lsass_dump_with_taskmgr.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/unsigned_image_loaded_by_lsass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dump_lsass_via_procdump_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1036.005", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml" }, { "techniqueID": "T1057", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1016", "score": 29, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1005", "score": 28, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/sqlite_module_in_temp_folder.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1204.001", "score": 28, "showSubtechniques": false }, { "techniqueID": "T1203", "score": 27, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1033", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discocvery_with_env_vars_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/check_elevated_cmd_using_whoami.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_taskhost_processes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/user_discovery_with_env_vars_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_query.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getcurrent_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_user_discovery_with_whoami.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1140", "score": 22, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/certutil_with_decode_argument.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_using_memory_as_backing_store.yml" }, { "techniqueID": "T1018", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_nltest.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_computer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaincontroller_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_controller_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadcomputer_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_system_discovery_with_adsisearcher.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1560.001", "score": 18, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/icedid_exfiltrated_archived_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_winrar.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/anomalous_usage_of_7zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_7_zip.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/7zip_commandline_to_smb_share_path.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1076", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1056.001", "score": 22, "showSubtechniques": false }, { "techniqueID": "T1055", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_remote_thread_to_known_windows_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/trickbot_named_pipe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_create_remote_thread_to_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cobalt_strike_named_pipes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/create_remote_thread_in_shell_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_createremotethread_in_browser.yml" }, { "techniqueID": "T1021.001", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_in_firewall_rule.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml" }, { "techniqueID": "T1047", "score": 17, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1189", "score": 20, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { "techniqueID": "T1059", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_distinct_processes_created_in_windows_temp_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/chcp_command_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_spawned_cmd_or_powershell_process.yml" }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1553.002", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1049", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_arp.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_netstat.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/network_connection_discovery_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getnettcpconnection_with_powershell_script_block.yml" }, { "techniqueID": "T1116", "score": 19, "showSubtechniques": false }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1133", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1074.001", "score": 18, "showSubtechniques": false }, { "techniqueID": "T1112", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_reg_exe_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/revil_registry_entry.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1503", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1543.003", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xmrig_driver_loaded.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_driver_loaded_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sc_exe_manipulating_windows_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmd_echo_pipe___escalation.yml" }, { "techniqueID": "T1136.001", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_local_admin_accounts_using_net_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_new_local_admin_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/short_lived_windows_accounts.yml" }, { "techniqueID": "T1555.003", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/non_chrome_process_accessing_chrome_default_dir.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml" }, { "techniqueID": "T1003", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attacker_tools_on_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mimikatz_with_powershell_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_ms_debuggers_z_option.yml" }, { "techniqueID": "T1041", "score": 17, "showSubtechniques": false }, { "techniqueID": "T1087.001", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/local_account_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getlocaluser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_user_account_with_powershell_script_block.yml" }, { "techniqueID": "T1036", "score": 13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_writes_to_system_volume_information.yml" }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1505.003", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/w3wp_spawning_shell.yml" }, { "techniqueID": "T1046", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1574.002", "score": 15, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/msmpeng_application_dll_side_loading.yml" }, { "techniqueID": "T1218.011", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_hunt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_with_no_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_lockworkstation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_dnsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_startw.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll_loading_dll_by_ordinal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_process_creating_exe_dll_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_dllregisterserver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_rundll32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/rundll32_control_rundll_world_writable_directory.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_plugininit.yml" }, { "techniqueID": "T1073", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1087.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_net_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_account_discovery_with_dsquery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/adsisearcher_account_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_user_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainuser_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/schcache_change_by_app_connect_and_create_adsi_object.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduser_with_powershell_script_block.yml" }, { "techniqueID": "T1085", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1136.002", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1021.002", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/write_executable_in_smb_share.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_psexec_with_accepteula_flag.yml" }, { "techniqueID": "T1100", "score": 16, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1190", "score": 14, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/unified_messaging_service_spawning_a_process.yml" }, { "techniqueID": "T1518.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1119", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1555", "score": 12, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___credential_extraction_lazagne_command_options.yml" }, { "techniqueID": "T1043", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1584.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1583.001", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1063", "score": 15, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1045", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1059.007", "score": 10, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_ldap_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/cmdline_tool_not_executed_in_cmd_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ms_scripting_process_loading_wmi_module.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/jscript_execution_using_cscript_app.yml" }, { "techniqueID": "T1027.002", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1562.001", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/attempt_to_stop_security_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_app_hotkeys.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_norun_windows_app.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_cmd_application.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_registry_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_disableantispyware_reg.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_firewall_with_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_taskkill.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_folderoptions_windows_feature.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_task_manager.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/hide_user_account_from_sign_in_screen.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_controlpanel.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_behavior_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_amsi_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_disable_security_monitoring.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_number_of_service_control_start_as_disabled.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_windows_smartscreen_protection.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/unload_sysmon_filter_driver.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_kill_base_on_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_systemrestore_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_etw_through_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml" }, { "techniqueID": "T1036.004", "score": 14, "showSubtechniques": false }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1113", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/remcos_rat_file_creation_in_remcos_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wav_file_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_image_creation_in_appdata_folder.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1219", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1102.002", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1560", "score": 12, "showSubtechniques": false }, { "techniqueID": "T1012", "score": 11, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1106", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml" }, { "techniqueID": "T1571", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1110", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_excessive_authentication_failures_alert.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_assume_role_policy_brute_force.yml" }, { "techniqueID": "T1090", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1035", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1573.001", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1569.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_service_in_suspicious_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_usage_of_sc_service_utility.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/malicious_powershell_executed_as_a_service.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_psexec.yml" }, { "techniqueID": "T1135", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1068", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/spoolsv_suspicious_process_access.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml" }, { "techniqueID": "T1059.006", "score": 11, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1143", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1124", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1173", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1588.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1114.002", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_rights_delegation.yml" }, { "techniqueID": "T1518", "score": 9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1102", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1559.002", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1132.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1564.003", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1587.001", "score": 10, "showSubtechniques": false }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1548.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/net_profiler_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fodhelper_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sdclt_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_runas_elevated.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wsreset_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_mmc_load_unsigned_dll.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/slui_spawning_a_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/silentcleanup_uac_bypass.yml" }, { "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_icedid_regsvr32_cmdline.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml" }, { "techniqueID": "T1071.004", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_record_changed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml" }, { "techniqueID": "T1170", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1088", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1584.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1007", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_processes_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1117", "score": 8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___first_time_seen_cmd_line.yml" }, { "techniqueID": "T1078.002", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/identify_new_user_accounts.yml" }, { "techniqueID": "T1090.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1099", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1590.002", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1583.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1218.005", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_url_in_command_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rundll32_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_mshta_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_inline_hta_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_mshta_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/office_product_spawn_cmd_process.yml" }, { "techniqueID": "T1070.006", "score": 9, "showSubtechniques": false }, { "techniqueID": "T1070.001", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_event_log_service_behavior.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_logs_using_wevtutil.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_event_log_cleared.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1009", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1021.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1065", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1070", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/usn_journal_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/process_deleting_its_process_file_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/fsutil_zeroing_file.yml" }, { "techniqueID": "T1027.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1562.004", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/processes_launching_netsh.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/processes_created_by_netsh.yml" }, { "techniqueID": "T1003.004", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1027.005", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_creating_thread_mutex.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_enable_smb1protocol_feature.yml" }, { "techniqueID": "T1552.001", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1048.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/plain_http_post_exfiltrated_data.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/multiple_archive_files_http_post_traffic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/network/dns_query_length_with_high_standard_deviation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_long_dns_txt_record_response.yml" }, { "techniqueID": "T1066", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1074.002", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1003.003", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/secretdumps_offline_ntds_dumping_tool.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ntdsutil_export_ntds.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml" }, { "techniqueID": "T1137", "score": 8, "showSubtechniques": false }, { "techniqueID": "T1078.003", "score": 7, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_excessive_user_account_lockouts.yml" }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1003.002", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/extraction_of_registry_hives.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/sam_database_file_access_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/esentutl_sam_copy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_windows_script_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excel_spawning_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml" }, { "techniqueID": "T1134", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" }, { "techniqueID": "T1195.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1590", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1027.003", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1001.002", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1546.003", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_wmi_event_subscription_persistence.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml" }, { "techniqueID": "T1075", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550.002", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_dest_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___ptt_pth_kerb_ntlm_origin_device.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_pass_hash.yml" }, { "techniqueID": "T1547.009", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1570", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1194", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1023", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1069", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1071", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1098", "score": -8, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_successful_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_delete_policy.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_iam_failure_group_deletion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml" }, { "techniqueID": "T1566.003", "score": 6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml" }, { "techniqueID": "T1084", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1221", "score": 7, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1550", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1037", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1015", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1090.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1564.001", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/disable_show_hidden_files.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml" }, { "techniqueID": "T1546.008", "score": 5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/overwriting_accessibility_binaries.yml" }, { "techniqueID": "T1038", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1573.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1585.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1110.003", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_attempting_to_authenticate_using_explicit_credentials.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_disabled_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_ntlm.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_remotely_failing_to_authenticate_from_host.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_invalid_users_failing_to_authenticate_from_host_using_kerberos.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/multiple_users_failing_to_authenticate_from_host_using_kerberos.yml" }, { "techniqueID": "T1586.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1120", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1087", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/enumerate_users_local_group_using_telegram.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml" }, { "techniqueID": "T1574.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1020", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_renamed_rclone.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_rclone_command_line_usage.yml" }, { "techniqueID": "T1158", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1039", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_connectivity_via_powersploit_modules.yml" }, { "techniqueID": "T1040", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1055.001", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1589.002", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1095", "score": 6, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1499", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.007", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/uninstall_app_using_msiexec.yml" }, { "techniqueID": "T1090.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1028", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1210", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml" }, { "techniqueID": "T1056", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1566", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_email___uba_anomaly.yml" }, { "techniqueID": "T1213", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1071.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1568", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1218.001", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_renamed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_spawn_child_process.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_html_help_url_in_command_line.yml" }, { "techniqueID": "T1587", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1583.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1598", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1102.001", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.002", "score": -13, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getdomaingroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getadgroup_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_adsisearcher.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_wmic.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/getwmiobject_ds_group_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/elevated_group_discovery_with_powerview.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/domain_group_discovery_with_dsquery.yml" }, { "techniqueID": "T1572", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1069.001", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_get_localgroup_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery_with_script_block_logging.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wmic_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_wmiobject_group_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/net_localgroup_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml" }, { "techniqueID": "T1567.002", "score": 4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/gsuite_drive_share_in_external_email.yml" }, { "techniqueID": "T1188", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1021.006", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1560.003", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1584.004", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1223", "score": 5, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1208", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1587.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml" }, { "techniqueID": "T1497", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1003.005", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1588.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1008", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1114", "score": 3, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_pst_export_alert.yml" }, { "techniqueID": "T1110.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1558.003", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___detect_kerberoasting.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml" }, { "techniqueID": "T1091", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1585.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1596.003", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1093", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1487", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1561.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1094", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1055.012", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1589", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1496", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1197", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/bitsadmin_download_file.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_start_bitstransfer.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/bits_job_persistence.yml" }, { "techniqueID": "T1586.001", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1014", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1145", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1552.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1071.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1199", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_in_develop.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/github_commit_changes_in_master.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml" }, { "techniqueID": "T1486", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/samsam_test_file_write.yml" }, { "techniqueID": "T1588.004", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1036.002", "score": 4, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1067", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1097", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1547.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1550.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1003.006", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1595.002", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml" }, { "techniqueID": "T1485", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/high_file_deletion_frequency.yml" }, { "techniqueID": "T1593", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1529", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1555.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1589.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1588.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1557", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1587.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1213.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1025", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1201", "score": -5, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/password_policy_discovery_with_net.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domainpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_addefaultdomainpasswordpolicy_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_aduserresultantpasswordpolicy_with_powershell.yml" }, { "techniqueID": "T1567", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1583.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1036.003", "score": -4, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/system_processes_run_from_unexpected_locations.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/execution_of_file_with_spaces_before_extension.yml" }, { "techniqueID": "T1497.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1016.001", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1542.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1498", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1584.003", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1573", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1074", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1114.001", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/mailsniper_invoke_functions.yml" }, { "techniqueID": "T1080", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1482", "score": -9, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell_script_block.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_domaintrust_with_powershell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/nltest_domain_trust_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_command_line_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_azurehound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/dsquery_domain_discovery.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/detect_sharphound_file_modifications.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/get_foresttrust_with_powershell.yml" }, { "techniqueID": "T1098.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1562.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1104", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1072", "score": 2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml" }, { "techniqueID": "T1027.004", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1115", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1053.002", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1500", "score": 3, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1484.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1176", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1506", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1542.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1052.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1553.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1098.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1489", "score": -6, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_delete_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___delete_a_net_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___attempt_to_disable_services.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/excessive_service_stop_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___disable_net_user_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/windows_security_account_manager_stopped.yml" }, { "techniqueID": "T1032", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1111", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1087.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1134.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1109", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1220", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/xsl_script_execution_with_wmic.yml" }, { "techniqueID": "T1550.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1480.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1114.003", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_admin_email_forwarding.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/o365_suspicious_user_email_forwarding.yml" }, { "techniqueID": "T1118", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1222.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1564.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1608.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1187", "score": 1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/petitpotam_network_share_access_request.yml" }, { "techniqueID": "T1574.006", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1125", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1560.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.003", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/wbemprox_com_object_execution.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/uac_bypass_with_colorui_com_object.yml" }, { "techniqueID": "T1055.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1555.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1483", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1565.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1606.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1191", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1059.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1589.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1497.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1037.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1217", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1559.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1048.002", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1001.003", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1036.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1492", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1594", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1021.005", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1568.001", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1218.004", "score": 2, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1186", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1103", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1055.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1096", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1484.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1216.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml" }, { "techniqueID": "T1030", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1174", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1102.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1122", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1534", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1530", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml" }, { "techniqueID": "T1557.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1550.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1543.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1090.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1561.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1528", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/add_defaultuser_and_password_in_registry.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/auto_admin_logon_registry_entry.yml" }, { "techniqueID": "T1546.011", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_file_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_for_creating_shim_databases.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml" }, { "techniqueID": "T1101", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/deprecated/suspicious_changes_to_file_associations.yml" }, { "techniqueID": "T1493", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1127.001", "score": -2, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_spawn.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/suspicious_msbuild_path.yml" }, { "techniqueID": "T1137.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1501", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1491.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.015", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/powershell_execute_com_object.yml" }, { "techniqueID": "T1001.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1218.008", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1172", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1527", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1588.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1183", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1123", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___illegal_access_user_content_via_powersploit_modules.yml" }, { "techniqueID": "T1592.002", "score": -1, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_defensive_tools_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { "techniqueID": "T1010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1029", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1547.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1134.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1138", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1592.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1488", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1590.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml" }, { "techniqueID": "T1590.005", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/wermgr_process_connecting_to_ip_check_web_services.yml" }, { "techniqueID": "T1092", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1078.004", "score": -16, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/cloud/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml" }, { "techniqueID": "T1539", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1042", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1222.001", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml" }, { "techniqueID": "T1557.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1608.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1574.012", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1182", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1026", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1556.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1591.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1568.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1553.005", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1126", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.009", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1053.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.013", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1214", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1110.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1070.002", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.010", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1205.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1565.003", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1137.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1494", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1552.006", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1546.012", "score": 0, "showSubtechniques": false, "comment": "https://github.com/splunk/security_content/blob/develop/detections/endpoint/registry_keys_used_for_privilege_escalation.yml" }, { "techniqueID": "T1146", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1564.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1558.001", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1200", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1504", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1056.004", "score": 1, "showSubtechniques": false }, { "techniqueID": "T1211", "score": 1, "showSubtechniques": false } ], "gradient": { "colors": [ "#66b1ff", "#ff66f4", "#ff6666" ], "minValue": 0, "maxValue": 60 }, "filters": { "platforms": [ "Windows", "Linux", "macOS", "AWS", "GCP", "Azure", "Office 365", "SaaS" ] }, "legendItems": [ { "label": "Low Priority", "color": "#66b1ff" }, { "label": "Medium Priority", "color": "#ff66f4" }, { "label": "High Priority", "color": "#ff6666" } ], "showTacticRowBackground": true, "tacticRowBackground": "#dddddd" }